Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
202

openSUSE Tumbleweed OpenSUSE-SU-2026-11176-1 kitty 0.47.4-2.1 Moderate

An update that solves one vulnerability can now be installed.. # kitty-0.47.4-2.1 on GA media Announcement ID: openSUSE-SU-2026:11176-1 Rating: moderate Cross-References: * CVE-2026-46604 CVSS scores: * CVE-2026-46604 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the kitty-0.47.4-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * kitty 0.47.4-2.1 * kitty-shell-integration 0.47.4-2.1 * kitty-terminfo 0.47.4-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46604.html . A moderate security advisory for openSUSE Tumbleweed addresses vulnerability in the kitty application, requiring updates.. openSUSE Tumbleweed security advisory kitty vulnerability CVE-2026-46604. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 03, 2026 moderate OpenSUSE
202

openSUSE Tumbleweed kitty Moderate CVE-2026-54057 Advisory 2026-11021-1

An update that solves one vulnerability can now be installed.. # kitty-0.47.3-1.1 on GA media Announcement ID: openSUSE-SU-2026:11021-1 Rating: moderate Cross-References: * CVE-2026-54057 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the kitty-0.47.3-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * kitty 0.47.3-1.1 * kitty-shell-integration 0.47.3-1.1 * kitty-terminfo 0.47.3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54057.html . Moderate security advisory for openSUSE Tumbleweed addressing CVE-2026-54057 in kitty version 0.47.3-1.1.. openSUSE Tumbleweed, kitty security update, CVE-2026-54057, Linux vulnerability, moderate security advisory. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 15, 2026 moderate OpenSUSE
197

Debian 11: DLA-4203-1 urgent: kitty code execution vulnerability fix

A vulnerability has been found in kitty, a fast, featureful, GPU based terminal emulator, which possible allows arbitrary code execution. CVE-2022-41322 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4203-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Tobias Frost June 01, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : kitty Version : 0.19.3-1+deb11u1 CVE ID : CVE-2022-41322 Debian Bug : 1020582 A vulnerability has been found in kitty, a fast, featureful, GPU based terminal emulator, which possible allows arbitrary code execution. CVE-2022-41322 In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup. For Debian 11 bullseye, this problem has been fixed in version 0.19.3-1+deb11u1. We recommend that you upgrade your kitty packages. For the detailed security status of kitty please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/kitty Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A significant security notice for Debian LTS highlights the risk of arbitrary code execution in kitty, necessitating an urgent update of the package.. Debian Security, kitty Update, Code Execution Risk, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 01, 2025 Critical Debian LTS
89

Fedora 40: kitty 2025-2fe21e3da5 Security Advisory Updates

Update to 0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-2fe21e3da5 2025-03-22 02:25:37.605934+00:00 -------------------------------------------------------------------------------- Name : kitty Product : Fedora 40 Version : 0.40.0 Release : 2.fc40 URL : https://sw.kovidgoyal.net/kitty Summary : Cross-platform, fast, feature full, GPU based terminal emulator Description : - Offloads rendering to the GPU for lower system load and buttery smooth scrolling. Uses threaded rendering to minimize input latency. - Supports all modern terminal features: graphics (images), unicode, true-color, OpenType ligatures, mouse protocol, focus tracking, bracketed paste and several new terminal protocol extensions. - Supports tiling multiple terminal windows side by side in different layouts without needing to use an extra program like tmux. - Can be controlled from scripts or the shell prompt, even over SSH. - Has a framework for Kittens, small terminal programs that can be used to extend kitty's functionality. For example, they are used for Unicode input, Hints and Side-by-side diff. - Supports startup sessions which allow you to specify the window/tab layout, working directories and programs to run on startup. - Cross-platform: kitty works on Linux and macOS, but because it uses only OpenGL for rendering, it should be trivial to port to other Unix-like platforms. - Allows you to open the scrollback buffer in a separate window using arbitrary programs of your choice. This is useful for browsing the history comfortably in a pager or editor. - Has multiple copy/paste buffers, like vim. -------------------------------------------------------------------------------- Update Information: Update to0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 8 2025 Pavel Solovev - 0.40.0-1 - Update to 0.40.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2352088 - CVE-2025-22870 kitty: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2352088 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-2fe21e3da5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Update to Kitty 0.40.0 in Fedora 40 addresses critical HTTP Proxy bypass issue. Immediate action recommended.. update, https, kovidgoyal, net/kitty/changelog/#detailed-list-of-changes, ---------------. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 22, 2025 Critical Fedora
89

Fedora 39: FEDORA-2024-c7b79bc227 Moderate: Kitty Rendering Improvements

rebuild for rhbz#2292712. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-c7b79bc227 2024-06-29 01:41:49.506039 -------------------------------------------------------------------------------- Name : kitty Product : Fedora 39 Version : 0.31.0 Release : 3.fc39 URL : https://sw.kovidgoyal.net/kitty Summary : Cross-platform, fast, feature full, GPU based terminal emulator Description : - Offloads rendering to the GPU for lower system load and buttery smooth scrolling. Uses threaded rendering to minimize input latency. - Supports all modern terminal features: graphics (images), unicode, true-color, OpenType ligatures, mouse protocol, focus tracking, bracketed paste and several new terminal protocol extensions. - Supports tiling multiple terminal windows side by side in different layouts without needing to use an extra program like tmux. - Can be controlled from scripts or the shell prompt, even over SSH. - Has a framework for Kittens, small terminal programs that can be used to extend kitty's functionality. For example, they are used for Unicode input, Hints and Side-by-side diff. - Supports startup sessions which allow you to specify the window/tab layout, working directories and programs to run on startup. - Cross-platform: kitty works on Linux and macOS, but because it uses only OpenGL for rendering, it should be trivial to port to other Unix-like platforms. - Allows you to open the scrollback buffer in a separate window using arbitrary programs of your choice. This is useful for browsing the history comfortably in a pager or editor. - Has multiple copy/paste buffers, like vim. -------------------------------------------------------------------------------- Update Information: rebuild for rhbz#2292712 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 20 2024 Pavel Solovev -0.31.0-3 - rebuild for rhbz#2292712 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-c7b79bc227' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Debian releases patches for fido, improving display performance and enriching command line interactions. Keep your system safe!. Fedora Updates, Terminal Emulator, Kitty Security, Software Security, Cross-Platform Applications. . LinuxSecurity.com Team

Calendar%202 Jun 29, 2024 Fedora
89

Fedora 39 Kitty Update: 2024-25b47765c6 Critical CVE-2023-36308 Fix

fix CVE-2023-36308. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-25b47765c6 2024-06-03 01:07:03.304526 -------------------------------------------------------------------------------- Name : kitty Product : Fedora 39 Version : 0.31.0 Release : 2.fc39 URL : https://sw.kovidgoyal.net/kitty Summary : Cross-platform, fast, feature full, GPU based terminal emulator Description : - Offloads rendering to the GPU for lower system load and buttery smooth scrolling. Uses threaded rendering to minimize input latency. - Supports all modern terminal features: graphics (images), unicode, true-color, OpenType ligatures, mouse protocol, focus tracking, bracketed paste and several new terminal protocol extensions. - Supports tiling multiple terminal windows side by side in different layouts without needing to use an extra program like tmux. - Can be controlled from scripts or the shell prompt, even over SSH. - Has a framework for Kittens, small terminal programs that can be used to extend kitty's functionality. For example, they are used for Unicode input, Hints and Side-by-side diff. - Supports startup sessions which allow you to specify the window/tab layout, working directories and programs to run on startup. - Cross-platform: kitty works on Linux and macOS, but because it uses only OpenGL for rendering, it should be trivial to port to other Unix-like platforms. - Allows you to open the scrollback buffer in a separate window using arbitrary programs of your choice. This is useful for browsing the history comfortably in a pager or editor. - Has multiple copy/paste buffers, like vim. -------------------------------------------------------------------------------- Update Information: fix CVE-2023-36308 -------------------------------------------------------------------------------- ChangeLog: * Sat May 25 2024 Pavel Solovev - 0.31.0-2 -switch to a maintained fork of imaging (fixes CVE-2023-36308) * Sat May 25 2024 Pavel Solovev - 0.31.0-1 - Revert "Update to 0.32.0" * Fri Jan 19 2024 Pavel Solovev - 0.32.0-1 - Update to 0.32.0 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-25b47765c6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Keep informed about Fedora 39's kitty update, which tackles security vulnerabilities related to CVE-2023-36309 and includes improvements for overall system efficiency.. Fedora Security Advisory, Kitty Terminal, Linux Terminal Emulator. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 03, 2024 Critical Fedora
89

Fedora 39: 2023-ab43e2ce21 Critical: Kitty Buffer Overflow Resolution

rebuild against golang-x-image 0.13.0 ---- version 0.30.1 ---- fix overflow when GLFW_IM_MODULE=ibus is set and ibus is not running ---- split out kitten clarify licenses for subpackages. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-ab43e2ce21 2023-10-31 00:04:53.921246 -------------------------------------------------------------------------------- Name : kitty Product : Fedora 39 Version : 0.30.1 Release : 2.fc39 URL : https://sw.kovidgoyal.net/kitty/ Summary : Cross-platform, fast, feature full, GPU based terminal emulator Description : - Offloads rendering to the GPU for lower system load and buttery smooth scrolling. Uses threaded rendering to minimize input latency. - Supports all modern terminal features: graphics (images), unicode, true-color, OpenType ligatures, mouse protocol, focus tracking, bracketed paste and several new terminal protocol extensions. - Supports tiling multiple terminal windows side by side in different layouts without needing to use an extra program like tmux. - Can be controlled from scripts or the shell prompt, even over SSH. - Has a framework for Kittens, small terminal programs that can be used to extend kitty's functionality. For example, they are used for Unicode input, Hints and Side-by-side diff. - Supports startup sessions which allow you to specify the window/tab layout, working directories and programs to run on startup. - Cross-platform: kitty works on Linux and macOS, but because it uses only OpenGL for rendering, it should be trivial to port to other Unix-like platforms. - Allows you to open the scrollback buffer in a separate window using arbitrary programs of your choice. This is useful for browsing the history comfortably in a pager or editor. - Has multiple copy/paste buffers, like vim. -------------------------------------------------------------------------------- UpdateInformation: rebuild against golang-x-image 0.13.0 ---- version 0.30.1 ---- fix overflow when GLFW_IM_MODULE=ibus is set and ibus is not running ---- split out kitten clarify licenses for subpackages -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 5 2023 Pavel Solovev - 0.30.1-1 - version 0.30.1 * Tue Oct 3 2023 Pavel Solovev - 0.30.0-3 - fix overflow when GLFW_IM_MODULE=ibus is set * Mon Oct 2 2023 Pavel Solovev - 0.30.0-2 - split out kitten - clarify licenses for subpackages -------------------------------------------------------------------------------- References: [ 1 ] Bug #2238648 - golang-github-seancfoley-bintree-1.2.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2238648 [ 2 ] Bug #2241851 - *** buffer overflow detected ***: terminated https://bugzilla.redhat.com/show_bug.cgi?id=2241851 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-ab43e2ce21' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Kitty 0.30.1release for Fedora 39 addresses buffer overflow vulnerability and provides clearer information on kitten licensing.. kitty terminal, terminal emulator, Fedora update, golang-x-image. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 31, 2023 Critical Fedora
89

Fedora 37: FEDORA-2023-a354113801 Critical: Kitty Clone Issue

fix clone-in-kitty + security fix rhbz#2196803. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-a354113801 2023-05-19 01:23:33.798443 --------------------------------------------------------------------------------Name : kitty Product : Fedora 37 Version : 0.26.5 Release : 5.fc37 URL : https://sw.kovidgoyal.net/kitty/ Summary : Cross-platform, fast, feature full, GPU based terminal emulator Description : - Offloads rendering to the GPU for lower system load and buttery smooth scrolling. Uses threaded rendering to minimize input latency. - Supports all modern terminal features: graphics (images), unicode, true-color, OpenType ligatures, mouse protocol, focus tracking, bracketed paste and several new terminal protocol extensions. - Supports tiling multiple terminal windows side by side in different layouts without needing to use an extra program like tmux. - Can be controlled from scripts or the shell prompt, even over SSH. - Has a framework for Kittens, small terminal programs that can be used to extend kitty's functionality. For example, they are used for Unicode input, Hints and Side-by-side diff. - Supports startup sessions which allow you to specify the window/tab layout, working directories and programs to run on startup. - Cross-platform: kitty works on Linux and macOS, but because it uses only OpenGL for rendering, it should be trivial to port to other Unix-like platforms. - Allows you to open the scrollback buffer in a separate window using arbitrary programs of your choice. This is useful for browsing the history comfortably in a pager or editor. - Has multiple copy/paste buffers, like vim. --------------------------------------------------------------------------------Update Information: fix clone-in-kitty + security fix rhbz#2196803 --------------------------------------------------------------------------------ChangeLog: *Wed May 10 2023 Pavel Solovev - 0.26.5-5 - minor spec cleanup, run tests, fix clone-in-kitty * Wed May 10 2023 Pavel Solovev - 0.26.5-4 - don't install kitty-open.desktop --------------------------------------------------------------------------------References: [ 1 ] Bug #2196802 - kitty: should not handle application/x-sh mime type by executing the script https://bugzilla.redhat.com/show_bug.cgi?id=2196802 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-a354113801' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Debian issues critical fix for puppy tackling access-in-puppy flaw in patch DEBIAN-2023-b753132045.. kitten terminal, security update, clone issue, security fix, Fedora 37. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 19, 2023 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200